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We review the study on a two way quantum key distribution protocol given imperfect settings 
through a simple analysis of a toy model and show that it can outperform a BB84 setup. We provide 
the sufficient condition for this as a ratio of optimal intensities for the protocols. 
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The study of quantum key distribution (QKD) [1[ has seen much development since its debut in the seminal work 
T?" 1 of Bennett and Brassard (BB84)@, where a new framework in secure communications based on physical laws was 
introduced. Security analysis which was initially more confined to studies within a theoretical framework was later 
extended to consider imperfections in a realistic setup [3j. While the former sees theoretical challenges where the 
(sometimes perfect) legitimate users, Alice and Bob are pit against an adversary, Eve who has perfect technological 
advantage, the latter addresses imperfections of the users, e.g. using weak coherent pulses instead of a singlephoton 
i— i, source (which immediately opens them to attacks like the notorious photon number splitting attacks (PNS) [J,|5( given 
42 ' lossy channels). Limitations on Eve is also not uncommonly studied, e.g. in [3] where Eve is limited to independent 
attacks and [6j where she is robbed of a quantum memory. 

While prepare and measure QKD schemes like BB84 are exhaustively studied, other families of QKD have received 
less treatment partly due to their more complicated nature. One such family is the 'two way QKD schemes' which 
arguably began with the Ping Pong protocol Q and was later followed by nonentangled versions reported in [8rfllj]. 
qh Essentially all shared the particular feature where Bob would send a qubit to Alice (forward path) who would encode 
using a flip (passive) operator to flip (retain) the state received. The qubit would then be returned to Bob (backward 
path) who would make a sharp measurement to deduce Alice's operation. As Alice's operation defines the encoding 
of the qubits, an Eve wishing to glean information must necessarily attack both the forward as well as the backward 
' path. Security is ensured by virtue of a control mode where Alice would randomly make a measurement instead and 
results would be compared on a public channel later to ascertain errors. Details of this may be found in [H, [lfj. It is 
• important to note that complete security analysis on such protocols has never been done though available calculations 
seem to suggest a higher level of robustness compared to BB84. Recently, a study on cloning unitary transformations 
, in seems to support this case. For the purpose of being specific, we will refer more often than not to LM05, which 
was the name given in [ll[ to the protocol Like BB84, a treatment for LM05 in terms of an imperfect source 
was done in [l3| . These works have suggested the robustness of LM05 over BB84 against PNS [H| . The results then 
[l3T | exhibited this at least for certain short and medium distances. However we feel there are some pertinent issues 
related to this protocol that have yet to receive rigorous highlight of which is our intent in this letter. 

The outline of our work is as follows. We first propose a toy model for such a two way protocol; i.e. a model 
protocol which essentially mimics the LM05. The model in some sense would distill only the most essential features 
of a two way QKD scheme and is inherently simpler to analyze. We should emphasize the point, that we are not 
proposing a new protocol. We then adopt the formalism for the optimal attack as described in [6] where Eve interacts 
with Alice/ Bob's qubit using a two dimensional ancilla and measures independently in the forward as well as the 
backward path. Let us note that such an attack is quite sufficient in terms of an individual attack on the BB84. 
Subsequently, we prove a simple theorem where the strength of interaction (attack) in the backward path should be 
equal to the one in the forward path for Eve's benefit. We note that this attack is partially inspired by the 'optimal 
incoherent attack' in [l(J. We proceed to consider the case for a non-ideal Alice/ Bob where they operate with a 
lossy channel as well as an imperfect photon source. The main objective of the toy model is to show that, in the 
face of these imperfections, its proper merit (and more importantly that of two way QKD) is really in its two way 
nature rather than Bob's 'deterministic' measurement [34j . We present the secure key rate which interestingly enough 
outperforms BB84 at all distances. 
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II. A TWO WAY QKD SCHEME; A TOY MODEL 



Let us first describe our model. We imagine a protocol, like LM05 where Bob sends to Alice a qubit prepared in one 
of four states \i±) where i = x,y of two preferred basis (Y and X). Alice then measures in either of the two basis 
chosen randomly; which projects it to an eigenstate of her measurement operator. The measured qubit, say \j±), 
where j = x,y then is subjected to a unitary transformation, / or Z as follows; 

I\j±)~>\j±) , Z\j±)^\j T ) (1) 

to retain or to flip the qubit respectively before resending to Bob. Bob then proceeds to measure in the basis he 
originally prepared the qubit in. At the end, they should reveal the basis over a public channel and only the cases 
where they share the same basis would Alice and Bob share the information of what unitary transformation was 
carried out; i.e. A + B mod 2 where A and B are the bit values resulting from Alice's and Bob's measurements. 

The model protocol is essentially LM05 with the added feature that Alice always measure before her unitary 
transformation and at first glance may seem simply as a two way channel derived from two BB84 'put back-to-back'. 
However it is important to note that the encoding is really derived from the sum of the bit content obtained from 
Bob's and Alice's stations. This fact forces Eve to attack both paths. One may argue that the transformation is rather 
spurious in that Alice could very well just prepare a state identical to her measurement outcome (or an orthogonal 
one) to resend; in fact in realistic situations, a qubit (usually a photon) is absorbed by a detector in a measurement. 
Nevertheless, we prefer to retain this model for the sake of having the projected qubit treated on. We will note later 
the merits of such an assertion. Another point worth mentioning is Alice's measurements in a certain sense allows for 
a detection of Eve, identical to the control mode in LM05 and does not require us to view errors in control mode as 
opposed to encoding mode separately (which is necessarily the case for LM05; the double CNOT attack for example 
in LM05 would induce errors in the control mode only pja]). In terms of efficiency though, it is immediately half that 
of LM05 due to the random choice of measurement basis. This should be analogous to having 50% control mode in 
LM05. 



A. Independent Attack; A Two Dimensional Ancilla 

We now analyze the model (for the sake of brevity, we hereafter refer to as ToM), under an independent attack 
using the formalism based on Q where Eve introduces her ancilla to interact with Alice/ Bob's qubit and measures 
thereafter. This is what is referred to as the 'optimal' attack in [f|, where the interaction between her ancilla and the 
travelling qubit be written in the Z basis as 

|0) |0 B ) -> |0) |0 B ) (2) 

|1) \Q E ) -> cosa|l) | 10b) +sina|0) |01 B ) 

where we consider a € [0, 7r/2]. The formalism considers Alice and Bob using the X and Y bases, thus immediately 
ensuring that the errors denoted by Alice and Bob would be the same in both bases and the state fidelities for Alice/ 
Bob and Eve would be (1 + cos a) /2 and (1 + sin a) /2 respectively @. These fidelities quoted are true since Eve 
has knowledge of basis (akin to a BB84 basis revelation). This is one of the niceties of our toy model as it allows 
for a direct import of such an attack's formalism. Without a measurement made by Alice, the qubit would be in an 
entangled state and further operations would be very messy and becomes somewhat complicated. In consideration 
of ToM, Eve attacks in the forward path by allowing her ancilla to interact with the qubit sent by Bob to Alice. A 
second attack is launched on the backward path assuming a fresh ancilla with similar unitary action (except that an 
angle (3 is used instead). It is easy to see, as noted in [l(| that Eve would be able to make the correct guess of Alice's 
encoding only in two possible instances; when she guesses the states in the forward and backward path correctly as 
well as when she guesses wrongly in both the paths. Thus we note that the fidelity of guessing the transformation 
correctly is given by 

(1 + sina) (1 + sin/?) (1 - sin a) (1 - sin/3) 

FE = 2 2 + 2 2 (3) 

(1 + sin a sin 0) 
2 ' 

In consideration of the information shared between Alice and Bob, a bit is shared only with probability 

(1 + cos a) (1 + cos/3) (1 — cos a) (1 — cos/3) 

F AB = g 2 + 2 2 (4) 

(1 + cos a cos ff) 
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and the probability for an erroneous bit would be 1 — Fab- A proper choice for the pair (a,/3) should be made to 
ensure that Eve's fidelity is maximized for any given disturbance experienced by Bob. We propose the following; 
given the 'independent ancilla based attack' as defined above, Eve achieves the highest fidelity when a = j3. In order 
to prove this, we begin with the following lemma. 

Lemma 1 For any pair (a, (3) ,a, (3 g [0, 7r/2], 3<J> such that cosacos/3 = cos 2 $ 

Proof. As a, f3 g [0, 7r/2], therefore < cosacos/3 < 1. It becomes immediate to see one may solve the following 
equality ^/cos a cos (3 — cos*!' = for $ g [0,7r/2]. ■ 

Theorem 2 Given a two way QKD protocol (ToM), an independent ancilla based attack using a two dimensional 
ancilla sees Eve achieving the highest fidelity when a = (3 Va, j3 € [0, 7r/2]. 

Proof. Starting with cosacos/3 = cos 2 <E>, Bob's disturbance may be written as 

(1 - cosacos/3) _ (l-cos 2 $) _ sin 2 $ 

2 = 2 = ~2~ (5) 

and Eve needs to find a pair (a, /3) that would maximize her fidelity for a given $. Writing cos a cos /3 = cos (a — /3) — 
sin a sin /3 we arrive at the following 

sin 2 $ 1 — cos (a — /3) + sin a sin (3 

— = 2 (6) 

sin 2 $ > sin a sin j3. 

The above inequality is valid as 1 — cos (a — (3) > and an equality is achieved when a = (3 and a = $. As Eve's 
fidelity function, Fe {ot,f3) is an increasing function of sin a sin /3, max [Fe (a, /3)] = Fe (a ~ (3) . ■ 

In the ensuing discussion, we consider a — (3 and Fe and Fab would reduce to Fe = (l + sin 2 a) /2 and 
Fab = (l + cos 2 a) /2 respectively. We plot below in Figure [TJ the information curves for Alice-Bob, Iab, and 
Alice-Eve, ItoM under this ancilla based attack. We also include the case where Eve uses the simple intercept resend 
(IR) attack and as ToM contains a basis revelation step, the IR would be analogous to BB84. In an IR, we may 
assume that Eve attacks only a fraction, say x of the qubits and her information of Alice's encoding for the attacked 
fraction would be complete. We see that this is in fact the best strategy for Eve. For comparison purposes, we 
include the corresponding curve for an optimal BB84 attack. 




0.1 0.2 0.3 0.4 0.5 

error 



FIG. 1: The above shows the information gained by Eve for different attack strategies employed. ItoM is the Alice-Eve mutual 
information in an ancilla base attack as described in text, Im is Eve's information using the IR attack and Ibbsa is Eve's 
information for an optimal independent eavesdropping in BB84. 
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III. THE IMPERFECT SOURCE 



Rather than a perfect single photon source, what Alice and Bob normally employ is in fact a source of which pulses 
emitted may contain more than one photon (or even zero) and the distribution is given by the Poissonian statistics. 
The probability to have n photons in a pulse is given by P n = fi n exp — \i / 'nl . The critical point in this drawback is 
that it opens Alice and Bob to an attack such as the photon number splitting (PNS) attack [H Q where Eve may 
steal a certain number of photons from a multiphoton pulse and make measurements on them while not disturbing 
the photons measured by Bob (thus not introducing any errors). In a BB84 setup, Lutkenhaus Q has shown that, 
given an error rate e, a secure key can only be generated from single photon contributions at the rate 

G=\ Pb 

where /(e) reflects the error correction efficiency (we take as 1.22 for simplicity) while h(e) is the binary entropic 
function. The average probability for detection at Bob's is denoted by pb and /3f, essentially reflects the fraction of 
bits from which a secure key may be extracted. The term r is a function for the amount of bits discarded due to 
privacy amplification and is defined as r(e) = log 2 1 + 4e — 4e 2 for e < 1/2 and 1 for e > 1/2. 



-f(e)h(e) + l3 b [l-r[- 



(7) 



A. ToM and Imperfect Source 



In order to consider the study of ToM given an imperfect setup, it is important to highlight our assumptions regarding 
Alice; 

1. Alice can actually measure a state and retain the projected state as a photon which she may subject to the next 
procedure. 

2. We further assume that Alice's measurement and instruments are completely efficient in the sense that the 
transmitivity of her instruments is really unity. 

Despite the fact that the two assumptions above are not realistic given today's technology; we should reiterate that 
we are not testing a new protocol. ToM is after all, only a toy model with which we hope to highlight the use of 
the 2 way channel for protocols like LM05. Hence, with regards to the first assumption, we are only interested in 
the case where Eve would exploit the imperfection of the photon source as well as the lossy channel; other than that 
we assume Alice's technological fantasies. The second assumption lies in the comfort of the fact that in LM05, the 
key rate does not suffer any imperfection of Alice's measurement in an encoding mode. However for the sake of the 
analysis of an imperfect source, we insist that Alice ignores/ cannot determine the number of photons in a pulse and 
in the multiphoton case, her measurement operator should act on all qubits in the pulse. This consequently presents 
a more pessimistic scenario for ToM. 



Lucamarini et al. [13[ gave a formula for secure key rate for LM05 similar to cq.© except for the absence of the 
'1/2' term as well as a different '/3' (which includes double photon contributions). The arguments for a two photon 
contribution in [l3[ carry over to ToM quite straightforwardly. However in ToM, while Eve's preferable attack would 
be the simple IR, the case for a two photon source is different. Eve could very well attack only the backward photon 
(subsequent to Alice's transformation) after retaining one of photons in the forward path. Once the basis is revealed 
publicly, she may make a sharp measurement on the hijacked photon and thus her fidelity of Alice's transformation 
would be perfectly identical to BB84's, (1 + sin a) /2 (a similar though then a heuristic justification for formulas used 
for LM05 was made in [16]). As for 3 photon pulses, unlike [l3j . basis revelation in ToM always allows for conclusive 
measurements for such pulses. Thus, with p t as the signal detected at Bob's station, the fraction from which to distill 
a secure key for ToM is given by 

^ = -\vt-(l-e-^^\\. (8) 

In order to determine how much information is to be discarded in privacy amplification, we need to ascertain the 
amount of Renyi information Eve may have access to. Let us note in passing that [l3| used the function r as defined 
in Q which we believe to be a very pessimistic estimate. 

As a quick refresher, we note that the Renyi entropy of order 2 for a random variable with n outcomes with p t 
being the probability for i-th outcome is given by (l7j 

n 

H B = -\og 2 J2p* (9) 
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and the Renyi information gain may be given by the difference between the apriori and aposteriori entropies [l8| . In 
a simple IR attack where Eve attacks only a fraction x of the qubits, her aposteriori Renyi entropy of Alice's encoding 
is given by 



log 2 



1 1 

22 + 22 



"2 l0g2 



1 1 

22 + 22 



-ilog 



= -lo 



fl 2 + 2 ) 



(10) 



82 



2 (.t/2)-1 



and her Renyi information gain (with 0.25a; = e) 

r t (e) = l + log 2 M*/ 2 )- 1 ] = 2e 

The Renyi information gain considering Eve's fidelity in the case of a two photon pulse is given by 

1 + log 2 { [(1 + sin a)/2] 2 + [(1 - sin a)/2] 2 } . 



(11) 



(12) 



With the disturbance e = (1 — cosa)/2, the amount of bits to be discarded in privacy amplification is thus 
log 2 (l + 4e — 4e 2 ), which is really the r from As r(e) > T t (e),Ve <E (0,0.5) (note that r t (e) is defined on e 
only up to 0.25) and since Alice and Bob cannot really ascertain where the errors are from, a safe choice for the 
amount of bits to be discarded in privacy amplification would be given by r. Thus the use of t is aptly and rigorously 
justified for calculating ToM's secure key rate. 

We proceed to consider in the following subsection, the secure key rate formula as a function of distance for ToM 
in a fiber based implementation. 



B. Secure Key Rates 

A fiber based setup has received fair treatment in modeling 0, EH, Ell and we will follow mostly [l!| where the overall 
gain for an encoded qubit/ photon detected by Bob's measurement as well as the overall QBER would be given 
respectively by 

p = p dark + 1 - e~ mt (13) 

and 

e a p dark + e det (1 - e~^t) 
e = (14) 

where r\ includes the transmitivity of internal optical components as well as the efficiency of Bob's detector. The 
transmitivity, t = 10~ 7 ' fc where 7 is coefficient value for fiber loss and Ik is the total distance a photon travels in 
the fiber (Ibbsa = 21tom)uM- The p dark term reflects the inevitable contribution from the dark counts while eo 
represents the error stemming from the dark counts and is given as 0.5. The optical system's alignment and stability 
is characterized by edet- 

Following the lead of [HI, [l5| and given equations (|TI13I14[) , our formula for key rate has the form identical to eq. (O 
except for the pi, substituted with p t and j3b with f3 t . As the agreed bit occurs only half the time, our comparison 
puts BB84 and ToM somewhat on equal footing. We plot in Figure [2] the secure key rates for ToM and c omp are 
them to the estimates for a BB84 with the experimental parameters of the GYS [HI [2(| as well as the KTH [ljf[2l| 
experiments. The term pt, and error for BB84 is also calculated using equations (12) and (13). 

It is thought that the toll of lossy channels on two way schemes should leave its performance somewhat wanting 
compared to BB84. However, our consideration for ToM here illustrates how it exceeds the key rate as well as 
performance distance of BB84 (we refer to Figure [5]). This may be understood as follows. If we consider purely the 
detection at Bob's station, for equal source intensity, then obviously pi, > p t . However, it is critical to remember 
from , the choice for source intensity should be optimal to achieve a maximum key rate for every distance. Writing 
the optimal intensity for BB84 and ToM as fi op t and kfi opt respectively, where k is a constant for a given distant, then 
Pb < pt when 

cxp (-r^optlCT™) > cxp (-T^optlO^Tr) (15) 
k > 10**. 
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FIG. 2: The above exhibits the secure key gain for ToM and BB84 for the parameters based on GYS and KTH. A numerically 
optimized fi at each distance for each protocol has been used for the distances plotted. 



Following the above inequality, it is obvious that (3 b < [3 t and writing the QBER of eq.(fT4"f as e e( f et + (e — e-det) p dark / 'p; 

it follows then that e& > et (e& and et are the QBERs for BB84 and ToM respectively). Hence the inequality (15) can 

be seen as a sufficient condition for the key rate of ToM to be greater than that of BB84. As an example, for GYS, 

we observe that at 7 = 0.21 and I = 41 km, k > 7.26. The ratio of optimal intensity for ToM to BB84 at this distance 

is about 9. Another example is for KTH parameters at 16 km, k > 2.1 while the ratio observed is 4.6. 

In the above calculations we have actually considered a perfectly efficient Alice. We now consider briefly the case 

1 ~^ 

when Alice's transmitivity, t\a < 1- The sufficient condition would now be corrected to k > 77^ IOto. We plot in 
Figure [3] and Figure 0] several curves for varying transmitivity of Alice for GYS and KTH parameters respectively. 
In consideration of the above parameters, the efficiency of Alice's equipments seems to require more attention for 
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FIG. 3: The above exhibits the secure key gain for ToM at r\A = 0.1, 0.7 and 1.0 compared to BB84 for the parameters based 
on GYS. 



improvement when compared to the channel transmitivity. 
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FIG. 4: The above exhibits the secure key gain for ToM at r\A = 0.2,0.5 and 1.0 compared to BB84 for the parameters based 
on KTH. 

IV. ACTUAL PHOTON CONTRIBUTIONS & ABSENCE OF PNS 

In this section we consider the case where Alice and Bob can actually determine the number of photons in a pulse 
contributing to the key (in an infinite decoy case for example; a simple study for decoy implementation of LM05 was 
made in 16]). In the absence of a PNS attack, the key rate for a BB84 is given by [22| 



R > \ {-Pbf(e b )h(e b ) 



Pi[l-r( ei )]} 



where p t = ViH l /i\, yi = p dark + m - p dark i]i and % = 1 - (1 - ry)\ e { = {e p 
number of photons in a pulse of concern. As for ToM, we write 

1 



(16) 

' edetVi) Ni an d i refers to the 

(17) 



R > g {-Pb.f(et)h(e t ) + Pl [l- r t {e x )] + p 2 [l - r(e 2 )]} 

which, not surprisingly, is somewhat similar to the decoy formula for LM05 [16j . We note at passing that the 
calculations for eq.(17) include the relevant rj for two way channels. 

The plot in Figure[5]for the key rates of BB84 and ToM using eq. (16) and eq. (17) shows a more favorable picture 
for the former after about 20 km and 30 km for GYS and KTH parameters respectively. The reason for the advantage 
for ToM at shorter distances would mainly be due to double photon contributions. This is indeed a reminiscence of 
the SARG04 protocol which suggests a better key rate compared to BB84 though under decoy implementations (in 
the absence of PNS) performs otherwise [23j . Relating the argument from 23] for SARG04, we can say that ToM 
performs better than BB84 under PNS considerations. It would be interesting to imagine that two way QKD schemes 
may just be a natural protocol against PNS attacks while possibly maintaining a higher level of robustness against 
noise. 



V. TWO WAY QUANTUM CRYPTOGRAPHIC SCHEME & CONTINUOUS VARIABLES 



In this short section, we should like to brief on a two way quantum cryptographic scheme in the framework of continuous 
variables (CV) as proposed in [24| . Although originally described in the language of finite dimensional Hilbert space, 
QKD has been explored in infinite dimensional Hilbert spaces in the framework of CV (2514301 ] . Encoding is done 
by amplitude modulation of coherent states with an independent pair of Gaussian variables, Q and P and decoding 
is done by measurements of the quadratures. Earlier proposals are, in philosophy not unlike its finite dimensional 
counterpart, i.e. as prepare and measure schemes. 
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FIG. 5: The above exhibits the secure key gain for ToM and BB84 based on eq.(16) and eq. (17) for GYS and KTH parameters. 

In [24| . a two way quantum cryptographic scheme in the continuous variable framework was proposed. This protocol 
sees Bob sending to Alice half an EPR pair, B2 while keeping one of the modes, B\ to himself. Alice would perform a 
Gaussian modulation by adding a stochastic amplitude to encode information before resending it to Bob who would 
then, together with B\ resort to either a homodyne detection (disjoint measurement of either Q or P quadratures) or 
a heterodyne detection (joint measurements of Q and P quadratures) . In analyzing the security of such a protocol, it 
was shown that Eve necessarily attacks both paths (channels) and given one mode Gaussian attacks, such a two way 
protocol provides improvement of the security threshold over one way protocols. This may be interpreted as having 
secure performance in a pair of channels of which individually would be too noisy for one way QKD. This effect is 
referred to by the authors as superadditivity and represents a definite advantage over one way QKD. Their proposal 
becomes essentially complete in the formulation of a hybrid protocol where Alice randomly chooses between a two 
way and a one way protocol, with the latter being identical to a prepare and measure scheme. The motivation for 
such a construction is as a measure against the most general collective attack on a two way scheme where Eve may 
perform an attack engendering correlation between both paths. Such correlations if exist, may be detected easily 
by the legitimate parties. Further studies have been made in (3lj where asymmetric Gaussian attacks between the 
two paths were considered and it was shown that the superadditive secure threshold holds. In [32|, a specific class 
of individual attack using combinations of Gaussian cloning machines on one of the protocols proposed in [24j was 
analyzed. 

VI. CONCLUSION 

In order to study what we believe to be the essentials of a two way QKD scheme (LM05) rigorously, we proposed a 
simple toy model, ToM. Beginning with an independent attack using a two dimensional ancilla, we proved a simple 
but relevant theorem and argue what the best independent attack should be for Eve. While an IR attack proves to 
be the more reasonable choice for concern, given an implementation with an imperfect photon source, we had had to 
resort to consider Eve's Renyi information gain for the double photon contribution case instead. We believe our use 
of key rate formulas and the like are more rigorously justified. We proceed to ascertain the secure key rates using 
BB84 based experimental parameters of GYS and KTH. 

Considerations for a completely efficient Alice shed a favorable light on ToM in comparisons against BB84 for both 
sets of parameters. This highlights an important feature of two way schemes, i.e. the inclusion of double photon 
contributions play a very significant role in key generation and allows for a higher key rate compared to BB84 despite 
the relatively extreme toll of lossy channels on ToM. We derived a sufficient condition for ToM's advantage over BB84 
and later noted for the parameters above, the ultimate culprit seems to be the transmitivity of Alice's equipments. 

On the other hand, in the absence of a PNS attack, Alice's ability to ascertain the contributing photon yields results 
in ToM displaying lower key rates compared to BB84 after a certain distance. This is quickly compared to the case 
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for SARG04, a protocol designed with the intention of combating the PNS. 

We hope to think that the toy model here would pronounce the interesting features of an actual two way QKD 
scheme like LM05. We believe the key rate formula for ToM is more pessimistic than that used or ought to be for a 
proper LM05 [l3[ especially given the appendage of the half factor term as well as the exclusion of three photon term. 
More importantly, in ToM, Eve's attack tends to leave her with equal amount of information about Alice encoding 
as well as Bob's measured state. This is not the case for LM05 which sees an asymmetry between the two, hence 
allowing for Alice and Bob to engage in a reverse reconciliation procedure [l5j that should in principle decrease the 
amount of information to be discarded in privacy amplification. A note worthy of mention is that the theory of two 
way QKD protocols boasts of higher elements of robustness against BB84 while previous studies in the face of lossy 
channels on the other hand have understandably suggested otherwise. Hence we believe our result should provide a 
breath of fresh air and effectively proposes for a more serious consideration of two way protocols. In the realm of CV 
quantum cryptography, promising results have been established in 0, HU, [32| spelling a definite advantage of two 
way protocols over its one way predecessor. 
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